Skip to content
Back to Blog
medium severity August 24, 2026 · 4 min read Unverified claim — what this is

HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed

If you were named in this filing, here’s what is being claimed, and what it would mean for you.

Connecticut’s Department of Social Services confirmed that an unauthorized person reached a HUSKY provider payment account and obtained claims and payment information for about 41,000 members. Social Security numbers, bank accounts, and electronic health records were not taken. Official letters offering free identity monitoring started going out by mail on August 21, 2026.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed

On August 21, 2026, the Connecticut Department of Social Services said Gainwell Technologies — the company that processes HUSKY Health payments — found unauthorized access to certain payment accounts on the HUSKY provider portal. Gainwell learned of it on June 25, 2026. The state says the outsider first got into a provider’s reimbursement account on June 18, 2026.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

DSS says that person obtained claims and payment information for about 41,000 HUSKY members: full name; an identification number tied to the provider’s payment account or a Medicaid claim; dates of medical services; information about services received and how they were billed; amounts paid; and, where it applied, other health insurance policy and group numbers. Electronic health records, Social Security numbers, and financial account information were not taken. Letters to affected people started going out by postal mail on August 21, 2026, with an offer of credit and identity monitoring. DSS has not reported evidence that the information was misused. This is the second HUSKY/Gainwell provider-portal incident in 2026; a separate May notice covered about 22,500 people.

The part most coverage will undersell

Almost every account of this incident will lead with what was not taken: no Social Security numbers, no bank accounts, no electronic health records. That is true, and it is better than the alternative. It is also the least useful sentence if you are trying to decide whether this touches your life.

What the outsider actually has, according to the state, is a named list of HUSKY members plus the billing trail of their care — when services happened, what was billed, what was paid, the numbers used to process those claims, and, for some people, the policy and group numbers of their other insurance. That is not your doctor’s chart. It is the invoice of your care, with your name on it.

Someone who has that can call and mention a real visit or a real payment and sound like HUSKY, a clinic, or a billing office. They can also try to bill new services using a real claim number and a real other-insurance policy number. DSS said the activity looked financially motivated, not aimed at collecting patient files. That is not comfort. It means they took the file that is useful for billing fraud and for a call that already knows too much about you.

No public scan can tell you whether you were in this specific incident. The only official signal is the letter DSS said it began mailing on August 21, 2026.

What to actually expect

  • If you were included, a letter by U.S. mail — not a surprise text, not a cold call — offering free credit and identity monitoring and fraud support. Mail can run late or go to an old address, so a delay is not proof either way.
  • A second, separate paper trail if you were also in the May 2026 incident (about 22,500 people). That was a different notice about the same kind of portal. Do not assume one letter covers both.
  • Calls, texts, or emails that already know you are on HUSKY, a service date, or an amount paid. Treat those as scams. The state’s own notice is a letter.
  • No reset of your Social Security number or bank login. Those were not in this file. The live risk is someone using your claim or other-insurance numbers, or using the details of your care to get you to talk.

What you can and cannot fix

What left that payment account cannot be pulled back. If your name, claim or payment-account number, service dates, billed services, payment amounts, or other insurance policy and group numbers were in it, they are out. There is no recall, and no company can delete the copy the outsider already has.

  • Use the official letter. Enroll in the monitoring and fraud support DSS is offering. That is the one remedy tied to this incident, and it is how you get help if someone later tries to open credit in your name.
  • Read every HUSKY claim and every other-insurance explanation of benefits. Look for visits, tests, or bills you do not recognize. Medical billing fraud is the use that matches what was taken. Report unknown claims to HUSKY and to any other insurer on the letter.
  • Do not confirm anything to anyone who contacts you first about this claimed breach, a “locked” HUSKY account, or a payment you need to “verify.” The state said it is writing by mail. Hang up and use a number you already have from a card or a prior official letter.
  • Shrink the public listings that attach a phone, a home address, relatives, and past addresses to your name. A bare billing record is awkward on its own. It becomes dangerous when it is joined to people-search pages that tell a stranger how to reach you and who lives with you. Those listings, unlike the stolen file, can actually be removed. That is the lever you still have.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on HUSKY Health.

  1. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
HUSKY Health is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed August 24, 2026
Affected Unconfirmed
Data exposed Full namesMedicaid or claim identification numbersdates of medical servicesbilled services detailspayment amountsother health insurance policy and group numbers
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email